poster-hero

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's example HTML fetches CSS from 'cdn.tailwindcss.com' and typography from 'fonts.googleapis.com'. These are well-known services used for web styling and font delivery.
  • [COMMAND_EXECUTION]: The example poster design (in 'example.html') includes an illustrative command '$ pnpm dlx html-anything'. This is static text used for visual presentation and does not instruct the agent to execute shell commands.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface:
  • Ingestion points: User-provided marketing content and data specified in the 'example_prompt' in 'SKILL.md'.
  • Boundary markers: Absent; there are no delimiters or instructions to ignore potential commands embedded in user data.
  • Capability inventory: HTML, CSS, and SVG generation for visual layout rendering.
  • Sanitization: Absent; the skill does not specify filtering or escaping of user input before rendering into the poster template.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — poster-hero